VendorsChamilochamilo_lmsany version
Vulnerabilities

Chamilo LMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

91CVEs
CVE-2023-34962
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
Published 2023-06-08 · Modified
8.1EPSS 0.007
CVE-2025-59541
Chamilo: CSRF Vulnerability in Project Deletion
Published 2026-03-06 · Analyzed
8.1EPSS 0.002
CVE-2026-31941
Server-Side Request Forgery (SSRF) in Chamilo LMS
Published 2026-04-10 · Analyzed
7.7EPSS 0.004
CVE-2012-4030
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
Published 2020-01-10 · Modified
7.5EPSS 0.013
CVE-2026-33710
Chamilo LMS has Weak REST API Key Generation (Predictable)
Published 2026-04-10 · Analyzed
7.5EPSS 0.005
CVE-2025-50196
Chamilo: OS Command Injection in /plugin/vchamilo/views/editinstance.php via POST main_database parameter
Published 2026-03-02 · Analyzed
7.2EPSS 0.027
CVE-2025-50197
Chamilo: OS Command Injection in /main/admin/sub_language_ajax.inc.php via POST new_language parameter
Published 2026-03-02 · Analyzed
7.2EPSS 0.027
CVE-2025-50195
Chamilo: OS Command Injection in /plugin/vchamilo/views/manage.controller.php
Published 2026-03-02 · Analyzed
7.2EPSS 0.027
CVE-2025-50193
Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database parameter
Published 2026-03-02 · Analyzed
7.2EPSS 0.026
CVE-2025-50194
Chamilo: OS Command Injection in /main/cron/lang/check_parse_lang.php
Published 2026-03-02 · Analyzed
7.2EPSS 0.026
CVE-2022-27421
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
Published 2022-04-15 · Modified
7.2EPSS 0.010
CVE-2025-50188
Error-based SQL Injection in Chamilo LMS
Published 2026-03-02 · Analyzed
7.2EPSS 0.007
CVE-2025-50191
Chamilo: Error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script
Published 2026-03-02 · Analyzed
7.2EPSS 0.005
CVE-2026-32894
Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Deletion of Any Student's Grade Result
Published 2026-04-10 · Analyzed
7.1EPSS 0.004
CVE-2026-33702
Chamilo LMS has an Insecure Direct Object Reference (IDOR)
Published 2026-04-10 · Analyzed
7.1EPSS 0.004
CVE-2026-34602
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
Published 2026-04-14 · Analyzed
7.1EPSS 0.004
CVE-2026-32930
Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership Check
Published 2026-04-10 · Analyzed
7.1EPSS 0.003
CVE-2025-52469
Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass
Published 2026-03-02 · Analyzed
7.1EPSS 0.003
CVE-2026-33706
Chamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher)
Published 2026-04-10 · Analyzed
7.1EPSS 0.003
CVE-2025-52564
Chamilo: HTML injection via open parameter
Published 2026-03-02 · Analyzed
6.9EPSS 0.002
CVE-2025-59544
Chamilo: Unauthorized access to update category of any user
Published 2026-03-06 · Analyzed
6.9EPSS 0.002
CVE-2019-1000017
Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable via ticket_id=[ticket number]. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.
Published 2019-02-04 · Modified
6.5EPSS 0.010
CVE-2026-34370
Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes
Published 2026-04-14 · Analyzed
6.5EPSS 0.004
CVE-2026-33737
Chamilo LMS has an XML External Entity (XXE) Injection
Published 2026-04-10 · Analyzed
6.5EPSS 0.004
CVE-2026-33708
Chamilo LMS has REST API PII Exposure via get_user_info_from_username
Published 2026-04-10 · Analyzed
6.5EPSS 0.004
CVE-2026-33141
Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data
Published 2026-04-10 · Analyzed
6.5EPSS 0.002
CVE-2025-59540
Chamilo: Stored Cross-Site Scripting (XSS) in Chamilo LMS Exercise Feedback
Published 2026-03-06 · Analyzed
6.4EPSS 0.002
CVE-2026-30876
Chamilo LMS: User enumeration vulnerability via response
Published 2026-03-16 · Analyzed
6.3EPSS 0.003
CVE-2021-37390
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
Published 2021-08-10 · Modified
6.1EPSS 0.008
CVE-2019-1000015
Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies. A ticket can be created with a XSS payload in the subject field. This attack appears to be exploitable via <svg/onload=alert(1)> as the payload user on the Subject field. This makes it possible to obtain the cookies of all users that have permission to view the tickets. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.
Published 2019-02-04 · Modified
6.1EPSS 0.008
CVE-2015-9540
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
Published 2020-01-04 · Modified
6.1EPSS 0.007
CVE-2022-27422
A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.
Published 2022-04-15 · Modified
6.1EPSS 0.006
CVE-2023-34961
Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.
Published 2023-06-08 · Modified
6.1EPSS 0.004
CVE-2026-32932
Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Edit
Published 2026-04-10 · Analyzed
6.1EPSS 0.003
CVE-2026-30882
Chamilo LMS: Reflected XSS in the session category listing page
Published 2026-03-16 · Analyzed
6.1EPSS 0.003
CVE-2025-52475
Chamilo: Reflected XSS via keyword_inactive parameter
Published 2026-03-02 · Analyzed
6.1EPSS 0.002
CVE-2025-52476
Chamilo: Reflected XSS via keyword_active parameter
Published 2026-03-02 · Analyzed
6.1EPSS 0.002
CVE-2025-52563
Chamilo: Reflected XSS via page parameter
Published 2026-03-02 · Analyzed
6.1EPSS 0.002
CVE-2013-6787
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.
Published 2013-12-05 · Modified
6.01 PoCEPSS 0.027
CVE-2026-1106
Chamilo LMS Legal Consent SocialController.php deleteLegal improper authorization
Published 2026-01-18 · Analyzed
5.5EPSS 0.004
← Prev2 / 3Next →